Industry

    AB 853's platform duties land in January 2027

    California's AI Transparency Act adds platform-side provenance duties on 1 January 2027. What changes at upload, and which metadata to audit on exports now.

    Versely Team8 min read

    Most coverage of California's AI Transparency Act stopped on 2 August 2026, the day the statute became operative. That was the wrong date to circle. The part of AB 853 that will actually change what happens when you press upload doesn't start until 1 January 2027, and it binds a group nobody in a creative pipeline belongs to: large online platforms and generative-AI hosting platforms. Which is exactly why it's worth reading now — the duty is theirs, but the file that arrives at their ingest endpoint is yours, and the two only work together if the file carries something to read.

    Three dates, three different targets

    AB 853 is not one obligation with one start date. It's a staggered set of duties pointed at three different kinds of company, and conflating them is the fastest way to misread what applies to you:

    Effective Who it binds Core duty
    2 Aug 2026 Covered GenAI providers (over 1,000,000 monthly users) Latent disclosures in generated content, plus a publicly accessible detection tool offered at no cost
    1 Jan 2027 Large online platforms Detect, surface and preserve provenance data on distributed content
    1 Jan 2028 Capture-device manufacturers Offer latent disclosures in captured content, embedded by default

    A separate 1 January 2027 duty lands on "GenAI hosting platforms," which the bill defines as a website or application that makes model weights or source code available for download. That one is a distribution-side gate, not a content-side one.

    Note the threshold difference, because it gets misquoted constantly: the provider duty attaches above one million monthly users, while the "large online platform" definition in the bill sets its bar at more than 2,000,000 unique monthly users over the preceding twelve months, across public-facing social media platforms, file-sharing platforms, mass messaging platforms and stand-alone search engines that distribute content users didn't create.

    What the platform duty actually requires

    The 1 January 2027 obligations on large online platforms are, in the bill's own structure, four distinct things:

    1. Detect provenance data compliant with established standards that is embedded in distributed content.
    2. Surface it through a user interface that discloses whether provenance data is available, and whether it indicates AI generation or alteration, or capture-device origin.
    3. Let users inspect the available provenance data — through the interface itself, through downloadable content, or through linked information.
    4. Refrain from stripping provenance data or digital signatures from content uploaded to or distributed on the platform.

    Point four is the one that changes engineering behaviour at every covered platform, and it's the one creators benefit from most directly. Platform re-encoding on ingest has been the single most reliable way for embedded metadata to vanish between a finished export and a published post. A duty not to strip is a duty to build an ingest pipeline that carries the fields through — which is a real change to how upload works, even though the visible surface change is just a small indicator on a post.

    Read the qualifiers on point four before you plan around it, though: the enacted text limits it to stripping done knowingly, to the extent technically feasible, and only to provenance data compliant with widely adopted specifications from an established standards body. That is three separate places for a platform to argue, and it is where the first disputes will land.

    The honest read: this creates no duty for you

    Worth stating plainly, because compliance content in this space routinely implies otherwise. AB 853 does not require an individual creator, agency or brand to attach provenance data to a file before uploading it. There is no creator-side attach obligation anywhere in the staggered schedule above. The duties run to providers, platforms, hosting platforms and device manufacturers.

    What changes for you is second-order, and it's the part that matters operationally: from January 2027, covered platforms will be reading your uploads for provenance data and rendering a visible answer based on what they find. If the file carries nothing, the honest platform answer is "no provenance data available" — which is not the same as "this is not AI-generated," but will be read that way by a meaningful share of viewers. The indicator is a signal about the file's metadata, not a verdict about the content.

    What that means for a real export

    Here's the gap, and it's the same one Article 50's machine-readable marking requirement opens from the other direction: the marking obligation sits with the model provider, the surfacing obligation sits with the platform, and the several hops in between — download, edit, composite, re-encode — belong to nobody in either statute.

    A generation that leaves a model carrying an embedded, machine-readable mark has to survive your editing step to still be there at ingest. Any multi-clip assembly is a re-encode: a new container, a new bitrate, a new file. Metadata that isn't explicitly carried through doesn't ride along by default. Versely's editor is EDL-based — one timeline, re-renderable — and the final export it produces is a genuinely new file, which is exactly the shape of step that a fragile metadata field does not survive. Nothing in AB 853 makes that anyone's violation. It just means the platform indicator you'll see in 2027 may be reporting on a mark your pipeline lost in 2026.

    Two related but separate things are worth keeping in different mental boxes:

    • Provenance data is machine-facing — a Content Credentials manifest or an embedded watermark that a detector reads. You mostly can't add it after the fact if the provider didn't embed it, and you can't guarantee it survives your own render.
    • Disclosure is human-facing — a platform's AI content label, a caption, an on-screen line. You control this at publish time, every time, regardless of what the file carries underneath.

    Versely applies no watermark on any plan, which is a deliberate product choice and a real differentiator for client work. It also means the second box is doing all the work: whatever a viewer is told about a Versely export is what you chose to tell them.

    The inventory worth doing before January

    Not a compliance programme. A one-afternoon audit, which is genuinely all this warrants:

    1. Pick one finished asset per pipeline you run — one image, one single-clip video, one multi-clip edited video.

    2. Check what each one carries at three points: straight out of the model, after your edit step, and after a test upload-and-redownload from each platform you publish to. Three checks per asset, not one. The interesting failures are all between the checkpoints, not at the start.

    3. Write down which fields survive to the end. For most editing pipelines the honest answer today is "none," and that is fine to know deliberately rather than assume optimistically.

    4. Decide your standing disclosure line now, before the platform indicator exists to be leaned on. A disclosure line nobody scrolls past is a copy problem, not a metadata problem, and it's the layer that works identically on every destination — including the ones AB 853 doesn't touch because they sit under the two-million threshold or outside California entirely.

    5. Map it across destinations once. The cross-platform labelling checklist is the version of this that survives contact with five different post composers, each with its own toggle in its own menu.

    The reason to do this in 2026 rather than reactively in January is that step two takes a week of ordinary publishing to observe honestly, and the answer is per-pipeline. You can't look it up.

    FAQ

    Does AB 853 require me to attach C2PA data to my videos?

    No. The bill places duties on covered GenAI providers, large online platforms, GenAI hosting platforms and capture-device manufacturers. An individual creator or brand publishing content has no attach obligation under it. What you may separately have is a platform-policy or advertising-disclosure obligation, which is a different requirement with a different trigger.

    If a platform shows "no provenance data" on my post, is that a problem?

    Not a legal one. It reports what the file carried, not what the content is. It can be a perception problem, which is the argument for a synthetic media disclosure you write yourself rather than an indicator you hope fires correctly.

    Does the 1 January 2027 date apply to every platform?

    No. The large-online-platform duties attach above the bill's stated threshold of more than 2,000,000 unique monthly users over the preceding twelve months, for public-facing social media, file-sharing, mass messaging and stand-alone search services distributing content their users didn't create. Smaller destinations are outside it.

    What is the "GenAI hosting platform" duty about?

    It's aimed at distribution of models rather than distribution of content: sites and applications that make model weights or source code available for download must not knowingly make available a GenAI system lacking the disclosure provisions the statute requires. If you download open weights, that gate sits between you and the host, not on your output.

    The date to act on is not January 2027. It's whenever you next ship a finished export — because the platform-side machinery arriving in January can only surface what your pipeline still had left to hand over.